Goal? LLMjacking and GPUjacking. Token mining is the new cryptomining.

Sysdig Threat Research Team (TRT) just published a report about an attack on an AWS environment featuring LLM use for recon, the classic "old credentials in a public S3 bucket" issue, and LLMjacking and GPUjacking as the objectives.

Highlights:

My take:

  1. LLMs are predictably collapsing the attacker timeline. Recon, planning, and iteration that used to take hours now happen in minutes.
  2. Pressure to implement AI in enterprises is surfacing basic security failures, especially in organizations without secure-by-design infrastructure.
  3. Expect more LLMjacking and GPUjacking. This is starting to look like cryptomining, except tokens are the new currency.

Sysdig threat research report